<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with Dual ISP Failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512411#M106477</link>
    <description>&lt;P&gt;I followed these instructions to set up ISP failover :&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the primary ISP1 goes down, it does indeed fail over to secondary ISP2, in every respect except that traffic doesn't use ISP2's NAT automatically. Upon failover, traffic continues trying to use the NAT rule associated with ISP1.&amp;nbsp; I have to manually go in and DISABLE ISP1's NAT rule, then traffic starts automatically flowing as expected via the NAT rule that exists for ISP2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What can I do so that this NAT switch happens automatically upon failover?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2022 21:48:11 GMT</pubDate>
    <dc:creator>pomologist</dc:creator>
    <dc:date>2022-08-19T21:48:11Z</dc:date>
    <item>
      <title>Issues with Dual ISP Failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512411#M106477</link>
      <description>&lt;P&gt;I followed these instructions to set up ISP failover :&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the primary ISP1 goes down, it does indeed fail over to secondary ISP2, in every respect except that traffic doesn't use ISP2's NAT automatically. Upon failover, traffic continues trying to use the NAT rule associated with ISP1.&amp;nbsp; I have to manually go in and DISABLE ISP1's NAT rule, then traffic starts automatically flowing as expected via the NAT rule that exists for ISP2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What can I do so that this NAT switch happens automatically upon failover?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 21:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512411#M106477</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2022-08-19T21:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Dual ISP Failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512458#M106485</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;
&lt;P&gt;Here are two screenshots that I hope will make things clearer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Something bizarre is going on.&amp;nbsp; ISP1 uses Eth1/1 Interface.&amp;nbsp; ISP2 uses Eth1/2 interface.&amp;nbsp; Bizarre thing is that &lt;STRONG&gt;Eth1/1 traffic is NATing through Eth 1/2's NAT rule&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;successfully&lt;/STRONG&gt;!&amp;nbsp; See photos.&amp;nbsp; What's going on? HELP!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Shot 2.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43232i37D1CE785828B350/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Shot 2.jpg" alt="Shot 2.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Shot 1.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43233i6E07C03B265843F3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Shot 1.jpg" alt="Shot 1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 15:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512458#M106485</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2022-08-21T15:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Dual ISP Failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512520#M106496</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176255"&gt;@pomologist&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Looking at your screenshot it seems you have missed one key component when configuring the NAT rules - Destination Interface.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1661167836263.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43257iC8B9B0D5F517DF02/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1661167836263.png" alt="Astardzhiev_0-1661167836263.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT rules are evaluated the same way as security rules - first match, top to bottom.&lt;/P&gt;
&lt;P&gt;When you configured only source and destination zone for the NAT (using any for source/dest IPs) traffic will always hit the first rule and never reach the second one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For that reason you must configure "Destination Interface", this will add the egressing interface as part of the matching criteria when evaluating the NAT rules.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;So when your primary ISP is up and traffic is using the primary default route your egress/destination interface will be eth1/1 (primary internet).&lt;/P&gt;
&lt;P&gt;When primary ISP is down and path monitor "disable" the primary default, traffic will take the backup default, buth this means egress/destination interface will be different, so this traffic will no longer match the first NAT rule and NAT evaluation will keep looking down reaching the second NAT rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that make sense&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 11:34:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512520#M106496</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-22T11:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Dual ISP Failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512537#M106502</link>
      <description>&lt;P&gt;THANK YOU SO MUCH!!! I don't know how I missed that!&amp;nbsp; Yes of course it makes perfect sense.&amp;nbsp; I so much appreciate you pointing this out.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 13:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-dual-isp-failover/m-p/512537#M106502</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2022-08-22T13:39:43Z</dc:date>
    </item>
  </channel>
</rss>

